Traffic : Multicast

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Traffic : Multicast

Base Rule

Information

General IP Multicast Information

Traffic Multicast Start

Sub Rule

Other Audit Success

Session Started

Traffic Muticast Deny

Sub Rule

Other Audit Failure

Auditing Session Failed

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

logid

<vmid>

<tag1>

Number

N/A

severity

<severity>

Number/Text

N/A

srcip

<sip>

IP Address

IP Address

srcport

<sport>

Number

N/A

srcintf

<sinterface>

Text/String/Number

N/A

dstip

<dip>

IP Address

IP Address

dstport

<dport>

Number

N/A

dstintf

<dinterface>

Text/String/Number

N/A

sessionid

<session>

Number/Text/String

N/A

proto

<protnum>

Number

N/A

action

<action>

<tag2>

Text/String

N/A

policytype

<policy>

Text/String

N/A

sentbyte

<bytesout>

Number

N/A

rcvdbyte

<bytesin>

Number

N/A

sentpkt

<packetsout>

Number

N/A

rcvdpkt

<packetsin>

Number

N/A